ruby on rails - Installing rails_admin causes SafeYAML warning -
After the 'bundle install' command, it seems that some older version of Libemal is used (see below).
Do not follow the instructions because the rails_admin is the engine (I think). Any idea how to solve this problem? AML Alert ---------------- You have an older version of LPML (0.1.5) before 0.1.6 installed on your system, Libyam Weak for a heap overflow that leverages the malicious YAML payload. For more information, see: https://www.ruby-lang.org/en/news/2014/03/29/heap-overflow-in-yaml-uri-escape-parsing-cve-2014-2525/ Most The simplest thing to do now, perhaps it is possible to update the bike in the latest version and enable the 'bundle-libayam' option, which will establish a vendor limbial with vulnerability: install gem psychology - - Enabled-bundle- Liyyamal Just 3 steps: Tell bundler with specific arguments bundle config build.psych --enable-bundled-libyaml < Code> psych Gem in Gemfile (Ruby 2.0+ has been sent with Psychological 2.0.0) Gem "Psycho", "~> 2.0.5" Run Bundler
install
Comments
Post a Comment